← Back to overview

A server-side request forgery (SSRF) vulnerability has been identified in PowerJob versions up to 5.1.2. The flaw resides in the function MuConnectionManager.getOrCreateConnection within the TestController.java file of the Transport Endpoint component. An attacker can exploit this vulnerability remotely without authentication. A public exploit is already available, increasing the risk of active exploitation. The vulnerability was responsibly disclosed to the project maintainers via a GitHub issue, but no response or patch has been issued yet. The lack of vendor response leaves users of affected versions exposed to potential SSRF attacks, which could allow attackers to make the server send requests to internal or external resources on behalf of the attacker.

Affected products

  • PowerJob up to 5.1.2

Related CVE's

  • CVE-2026-82630

Categories

  • Enterprise Applications
  • Web Technologies